The Federated States of Micronesia's one enacted operator-facing security-posture duty for a private-sector duty-bearer sits inside its general telecommunications regulatory law, and a second, broader critical-infrastructure cybersecurity framework is pending before its national legislature but had not yet passed as of September 2026.
The FSM Code's own online index, hosted by the Asian Development Bank-funded Legal Information System at fsmlaw.org, is an unofficial codification frozen at Public Law No. 12-12 of August 2001, and its 58 titles carry no Computer Crimes, Cybersecurity, or Electronic Transactions title or chapter as codified there; Title 11 (Crimes) stops at Chapter 12 (Sentencing) with no computer-offense chapter, and Title 21 (Telecommunications) as codified there holds only the original 2001-era Chapter 1 (General Provisions) and Chapter 2 (Telecommunications Corporation).
Because that codification is stale, the national legislature's own current public-law and bill archive at the Congress of the Federated States of Micronesia's website (cfsm.gov.fm) was searched instead.
Two companion bills were introduced in the Twenty-Third Congress on May 17, 2025: C.B. No. 24-15 would add a new Chapter 13 to Title 11 defining cybercrime offenses such as unauthorized access, computer-related fraud, and cyberstalking, an intruder-offense bill this jurisdiction's scraping row already names; and C.B. No. 24-14 (the Cybersecurity Act 2025), researched here, would add a new Chapter 4 to Title 21 establishing a critical-information-infrastructure cybersecurity framework, a National Cybersecurity Committee, and a national Computer Emergency Response Team (CERT-FSM).
Neither bill carried a Congressional Act number as of September 2026, meaning neither had passed the Congress.
No further search of the 18th through 23rd Congresses' enacted public-law titles surfaced any other cybersecurity, data-protection, or electronic-transactions statute; the only enacted operator-facing security duty found is Public Law No. 18-52 (2014), the 'FSM Telecommunications Act of 2014,' inserted as a new Chapter 3 of Title 21, and section 349(1)(b) of that chapter is this jurisdiction's coded telecommunications-safeguards instrument below.
No comprehensive data-protection or breach-notification statute exists for this jurisdiction's privacy row to carry a security-of-processing clause from, so there is no Test 2 seam to defer to here.
C.B. No. 24-14's Subchapter III (sections 407 through 412) creates the operator-facing duties coded as two proposed instruments below, one for the risk-management measures a critical-information-infrastructure owner must implement and one for the incident-reporting clock the same owner must meet.
Title 21's older Chapter 2 (Telecommunications Corporation) and the enacted Chapter 3 survive alongside the bill's proposed Chapter 4, so the Federated States of Micronesia Telecommunications Corporation, the Chapter 2 incumbent operator, continues to hold its own separate statutory powers; whether it is itself a Chapter 3 licensee bound by section 349(1)(b) is not established in the text located here and is recorded as an open question on that instrument.
C.B. No. 24-14's Subchapter V would separately require a person providing an accreditable cybersecurity service, such as a security operations center or penetration-testing service, to hold an accreditation from an officer the Secretary of Justice appoints; that duty binds a narrow class of security vendor this corpus's activity vocabulary cannot yet express, so it is named here in prose rather than filed as a coded instrument, the same treatment already given Vanuatu's near-identical cybersecurity service-permit regime.
Section 27 of the bill would delay Subchapter V's own commencement until the Secretary of Justice promulgates implementing regulations, later than the rest of the chapter's ordinary commencement on presidential approval.
Section 382 of the enacted Telecommunications Act of 2014 separately criminalizes unauthorized access to a communications facility, interception, and data damage or disruption, an intruder-offense chapter already within the scraping topic's computer-misuse family and not itself a security-topic duty on an operator or manufacturer.
No Central Bank or IT-risk directive for a licensed financial institution was located: the FSM Code's Title 29 (Commercial Banking), Chapter 6 (Regulation and Supervision of Banks, sections 601-627), uses the word 'security' only for loan collateral and carries no confidentiality, safeguards, or cyber provision, and no public website for a Federated States of Micronesia Banking Board or equivalent financial regulator could be located to check for a lower-visibility prudential directive (a guessed domain returned no DNS record), so that remains an open research gap rather than a confirmed absence.
Whether the World Bank, the Pacific Islands Forum, SPC, or the ITU assisted in drafting C.B. No. 24-14 was not established in the sources checked; that absence rests on the primary sources browsed directly, since a broader web search could not be run, so it is an open gap rather than a settled absence.
Several sources returned no usable text: fsmtc.fm (the Telecommunications Corporation's own site) and fsmgov.org each served only a JavaScript shell on both the compliant and browser tiers; the FSM Congress's legacy fsmcongress.fm domain failed with a certificate hostname mismatch at the TLS layer on every scheme tried, a genuine site-side misconfiguration rather than a bot wall, which is why the current cfsm.gov.fm domain was used instead; PacLII's Federated States of Micronesia index returned a Cloudflare CAPTCHA challenge, a stop rather than a wall to read past; and no working WIPO Lex jurisdiction profile page for the Federated States of Micronesia could be located by direct URL, so the cross-check used for other jurisdictions in this corpus is unavailable here.